Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F513B9F461436412A603E1E1057F0B1B64B94F98E9AB4A1CD9B8B2FC3ED4C4586D7FB8 |
|
CONTENT
ssdeep
|
768:vmbMnlKlpBqElQe//RWW8N5MU30gNVI+qPZOP4vaSo1bxi7ZJD/jObmbiwEfz0pA:vmglKlpBqElQe//RWW8N5MU30gNVI+qC |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bf3f3a382b8784c0 |
|
VISUAL
aHash
|
8181ffbfffffffff |
|
VISUAL
dHash
|
3b3b406181000000 |
|
VISUAL
wHash
|
0081fea0fcfcf8f0 |
|
VISUAL
colorHash
|
07007000000 |
|
VISUAL
cropResistant
|
3b3b406181000000,fbdbd3d29cdcbcbc |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 62 techniques to evade detection by security scanners and make reverse engineering more difficult.